6.9

CVSS4.0

CVE-2025-3668 - TOTOLINK A3700R cstecgi.cgi setScheduleCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has be…

πŸ“… Published: April 16, 2025, 4:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

6.9

CVSS4.0

CVE-2025-3667 - TOTOLINK A3700R cstecgi.cgi setUPnPCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been dis…

πŸ“… Published: April 16, 2025, 4:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

6.9

CVSS4.0

CVE-2025-3666 - TOTOLINK A3700R cstecgi.cgi setDdnsCfg access control

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed …

πŸ“… Published: April 16, 2025, 3:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:49 p.m.

9.8

CVSS3.1

CVE-2025-3495 - COMMGR - Insufficient Randomization Authentication Bypass

Delta Electronics COMMGR v1 and v2Β uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.

πŸ“… Published: April 16, 2025, 3:10 a.m. πŸ”„ Last Modified: Aug. 19, 2025, 12:11 a.m.

6.9

CVSS4.0

CVE-2025-3665 - TOTOLINK A3700R cstecgi.cgi setSmartQosCfg access control

A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit ha…

πŸ“… Published: April 16, 2025, 3 a.m. πŸ”„ Last Modified: April 22, 2025, 4:54 p.m.

6.9

CVSS4.0

CVE-2025-3664 - TOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access control

A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has bee…

πŸ“… Published: April 16, 2025, 3 a.m. πŸ”„ Last Modified: April 22, 2025, 4:53 p.m.

6.9

CVSS4.0

CVE-2025-3663 - TOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control

A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handler. The manipulation leads to improper access controls. The …

πŸ“… Published: April 16, 2025, 2:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:50 p.m.

7.5

CVSS3.1

CVE-2025-3698 -

Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.

πŸ“… Published: April 16, 2025, 2:24 a.m. πŸ”„ Last Modified: Nov. 13, 2025, 2 p.m.

6.1

CVSS3.1

CVE-2024-13452 - Contact Form by Supsystic <= 1.7.29 - Cross-Site Request Forgery to Stored Cross-Site Scripting via…

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29. This is due to missing or incorrect nonce validation on a saveAsCopy function. This makes it possible for unauthenticated attackers to update settings and inj…

πŸ“… Published: April 16, 2025, 2:12 a.m. πŸ”„ Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2025-2314 - User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13.5 due to insufficient input sanitization and output escaping on use…

πŸ“… Published: April 16, 2025, 1:45 a.m. πŸ”„ Last Modified: April 8, 2026, 5:11 p.m.
Total resulsts: 343921
Page 5256 of 34,393
Β« previous page Β» next page
Filters